<!-- https://zunderlabs.com/docs/concepts/hip3 · Markdown version of the page -->

# HIP-3 markets

How Guard handles builder-deployed perp dexes on Hyperliquid (trade.xyz and others): opt-in per dex, account-wide limits, the dex's own margin, thin books, halts and open-interest caps.

HIP-3 lets builders deploy perp dexes of their own on Hyperliquid. trade.xyz's `xyz` lists equities, indices, commodities and currencies; its coins are named `xyz:GOLD`, `xyz:XYZ100`. Guard judges them with the same nine rules as the main dex, on paper and testnet. Mainnet refuses HIP-3 markets for now.

:::note[Paper and testnet]
HIP-3 support is new (phase 2a). A mainnet config that names a HIP-3 market is refused.
:::

## Opt in per dex

`*` in your markets means every market of the **main** dex, never a HIP-3 one. Name a HIP-3 dex to let Guard trade it:

| Markets | Allows |
|---|---|
| `["*"]` (the default) | every main-dex market, no HIP-3 market |
| `["*", "xyz:*"]` | every main-dex market and every market of dex `xyz` |
| `["BTC", "xyz:GOLD"]` | BTC and xyz:GOLD only |

Guard reads at most two HIP-3 dexes. On a dex your markets do not name, Guard forwards nothing but cancels: orders, leverage and margin changes are refused (`dex_not_allowed`).

## One account, several margin accounts

On Hyperliquid each perp dex keeps its own margin account; you move USDC between them yourself. Guard adds them up:

- **Account-wide:** equity is the sum over the main dex and the dexes you named. The loss at the stop, open risk, the leverage cap, the position cap, the daily loss stop and the drawdown halt all measure that sum. A loss on `xyz` counts toward your daily stop like a loss on BTC.
- **Per dex:** each HIP-3 order is also cut to what that dex's own margin account can fund at the leverage Guard sets (`dex_margin` when not even the smallest order fits: move USDC to the dex first). Leverage is bounded by the coin's own maximum on its dex.
- **Fees:** HIP-3 deployers set a fee scale; a taker pays up to six times the main dex's rate. Guard counts the dex's real fee into each order's risk.

Removing a dex from your markets drops its account from the equity Guard measures, which can fire the daily stop or the drawdown halt. Close and move what is there first.

## What can go wrong on a HIP-3 market

| Risk | What Guard does | Code |
|---|---|---|
| Thin book: a stop fills only what lies within its limit | Cuts the order so the position takes at most half of the book between the stop and its worst fill | `thin_book` |
| The deployer halts the market and settles positions at the mark | Refuses new entries; sends no stop or close there (the venue settles) and tells you | `market_halted` |
| The market is at its open-interest cap | Refuses new entries | `open_interest_cap` |
| The dex margins in another token than USDC | Opens nothing there | `unsupported_market` |
| The deployer moves the oracle through your stop | Nothing it can detect: choose the deployers you trust in your markets | |

Positions on a dex your markets do not name are reported in Guard's status, never touched, not even by the [kill switch](https://zunderlabs.com/docs/concepts/kill-switch).
